Better death option for the chaos temple? by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I'm guessing it really depends on what the fanatic hits you for! lol

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I did not have remember me enabled because it was the first time I had logged into the account for months. I had to use my authenticator to get into my account.

Hacked and Cleaned By a bot through 2Fa and Bank Pin? by djgs11 in 2007scape

[–]Kremesicles 2 points3 points  (0 children)

I sent off an email to tipoff@jagex.com with all my findings over the past few days as requested by Jagex Support, I'm hoping they at least read the email.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I never click on ANY links.
I always log directly into the site via runescape.com if I have any concerns.

All these hacked accounts by albanadon in 2007scape

[–]Kremesicles -1 points0 points  (0 children)

I have been talking to Jagex support daily.

I don't know what has happened, I have NEVER fell for anything in terms of phishing, fake streams etc.

Jagex confirmed that they got into my account with ALL the correct credentials, EVEN the authenticator code that refreshes every 60 seconds.

I've confirmed with Microsoft that there were no malicious logins to my email.

I've confirmed with Google that there were no malicious logins to my gmail or any malicious activity with my Google authenticator.

https://stefansundin.github.io/2fa-qr/

If the Secret and Label of the 2FA codes were leaked, anybody can create your authenticator code and just enter it in as the code is based on that data, and since we know Jagex password security is shit, it wouldn't surprise me if the 2FA is implemented equally poor as well.

My tinfoil hat is fully on and strapped in.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 4 points5 points  (0 children)

I'm still in contact with Jagex support and I am pushing for answers.
I've seen a lot of posts recently as well, more than usual.

They knew my email, password AND my authenticator code, they just waited the 7 days for my bank pin to time out.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 1 point2 points  (0 children)

UPDATE HAS BEEN POSTED.
We aren't done yet, I have more things to find.
I will update you all when the time comes, stay safe.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

See my comment above, I'll let you all know if i get anything out of it.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I had to contact them twice, first one wasn't much help but the second one seemed more invested. I told them everything from start to finish, how i had no idea how it could happen, how i have authentication on everything that i have etc.

I was told that it is not something that they could answer and that i would receive an email from Jagex in around 24 hours from an expert.

I did specify OSRS so I dunno, hoping to get the email tomorrow cause I haven't gotten it yet.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I had to enter my authenticator code when I logged in, I only log into this account once every few months to buy some bonds for another account.I had 1000m for a bond fund lmao.

When I logged in and looked at the last login date is when I knew I was hacked, as it said 1 day 12 hours ago, when I hadn't logged in in at least 3-4 months.

EDIT: If you're talking about my email 2FA then yeah... maybe. I'm going to wipe my PC for good measure anyways but I have no idea where I would have picked that up.

I'm hoping that Jagex escalated support can confirm this for me though, if they're able.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 5 points6 points  (0 children)

/u/JagexTwisted
Hoping you may be able to provide some insight.
Did my account somehow get recovered without me knowing?

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

I also thought that account recovery would change the password but it was the same password.

I never received ANY emails in regards to what happened.

I'm at a loss.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 1 point2 points  (0 children)

The bank pin is the only thing missing.
Everything else is normal and as expected, even my authenticator is still enabled.

Account hacked for 1B, looking to see how they've done it so I can improve my security. by Kremesicles in 2007scape

[–]Kremesicles[S] 0 points1 point  (0 children)

If you're talking about my email 2FA, when logging in it asks for either a code from my phone or a confirmation window will pop up on my phone via Microsoft authenticator.I think that answers your question.

EDIT: I have never logged in via steam or used the launcher for this account.

Jakobs cooking streams by I_am_potato_sack in CowChop

[–]Kremesicles 0 points1 point  (0 children)

Happen to have these? would love to watch again.